CVE-2023-38259Apple Macos vulnerability

5 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An app may be able to access user-sensitive data.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Appleapple/macos_monterey12.6.8
CVEListV5apple/macosunspecified13.5+2
NVDapple/macos11.011.7.9+2
Appleapple/macos_big_sur11.7.9

🔴Vulnerability Details

1
GHSA
GHSA-38rm-v4v3-vhx2: An out-of-bounds read was addressed with improved input validation2023-07-27

📋Vendor Advisories

3
Apple
CVE-2023-38259: macOS Monterey 12.6.82023-07-24
Apple
CVE-2023-38259: macOS Big Sur 11.7.92023-07-24
Apple
CVE-2023-38259: macOS Ventura 13.52023-07-24